Win32k Callback Detouring: Defending the Return Path
Win32k callback detouring is a broader control-flow integrity problem: a legitimate GUI transition returns to a user-mode destination that has been redirected or modified. Detection should establish where callbacks are expected to land and whether preceding memory activity changed that trust relationship.
No callback-selection, detour implementation, or trigger instructions are included. Use supported symbols and build-aware tooling for analysis.
Control flow across a trust boundary
GUI operations cross a kernel boundary and may invoke user-mode callbacks before returning to application code. A detour can target callback data, executable bytes, or another control-flow object. The detector should therefore model the transition, destination provenance, page integrity, and source of any modification rather than relying on one table or function name.
Detection design
- Resolve user-mode callback destinations and require expected image backing.
- Compare relevant executable pages with the exact signed on-disk build.
- Monitor cross-process writes and protection changes in GUI processes.
- Capture stack samples around anomalous kernel-to-user transitions.
- Use CFG/CET telemetry and exploit-protection events where hardware and products expose them.
Version drift is a major operational risk. Callback sets, symbols, and implementation details change. Maintain baselines by Windows build, architecture, and patch level, and retire offsets when endpoints update.
Response and safe research
Preserve memory, thread stacks, loaded module versions, symbols, handles, source-target relationships, and code-integrity events. Compare endpoint build metadata before interpreting addresses. Volatility 3, PE-sieve, Moneta, and Microsoft Detours source can help defenders understand legitimate detouring patterns. Safe validation should inventory and compare untouched callbacks before and after normal Windows servicing, without creating an injection path.
ATT&CK, CVEs, and hardening
Depending on evidence, classify under T1055 Process Injection or T1574 Hijack Execution Flow. Callback detouring is a technique class, not automatically a CVE. Specific win32k vulnerabilities have separate CVEs, but naming one without exploit evidence creates a false claim. Keep Windows current, enable exploit protection and application control, reduce privilege, harden high-value GUI sessions, and collect memory-integrity telemetry.